Files
splunk-security_content/macros/crowdstrike_stream.yml
2024-07-31 11:10:41 +02:00

4 lines
247 B
YAML

definition: sourcetype="CrowdStrike:Event:Streams:JSON"
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
name: crowdstrike_stream